PlatformInfraCloudAzure

  1. In the navigation sidebar, select API permissions.

    API permissions

    By default, Microsoft grants your new application User.Read permission for Microsoft Graph. It's not required for Mondoo, so you can remove it.

  2. Select + Add a permission.

    Add permission in Entra

  3. From the list of Commonly used Microsoft APIs, select Microsoft Graph.

    API permissions

  4. Because Mondoo acts as a service, select Application permissions.

  5. Select expand all to see all permissions. Then select the required API permissions:

Microsoft GraphTypeDescription
Application.Read.AllApplicationRead all applications
Domain.Read.AllApplicationRead domains
IdentityProvider.Read.AllApplicationRead identity providers
IdentityRiskEvent.Read.AllApplicationRead all identity risk event information
IdentityRiskyUser.Read.AllApplicationRead all identity risky user information
Policy.Read.AllApplicationRead your organization's policies
Policy.Read.ConditionalAccessApplicationRead your organization's conditional access policies
Policy.Read.PermissionGrantApplicationRead consent and permission grant policies
RoleManagement.Read.AllApplicationRead role management data for all RBAC providers
SecurityActions.Read.AllApplicationRead your organization's security actions
SecurityEvents.Read.AllApplicationRead your organization's security events
ThreatAssessment.Read.AllApplicationRead threat assessment requests
ThreatIndicators.Read.AllApplicationRead all threat indicators
  1. Select the Add permissions button.

  2. To complete the process, select Grant admin consent for (your tenant name) and select the Yes button to confirm.